216.73.216.6

Exposing the Deception: Russian EFF Impersonators Behind Stealc & Pyramid C2

· Published 04/03/2025 22:43 · Modified 05/03/2025 16:39

Export JSON

Essential information

Published
04/03/2025 22:43
Modified
05/03/2025 16:39
Tags
2025-03-04 gaming phishing pyramid c2 russian-speaking stealc
Related entities
20 techniques (mitre), 2 malware

Description

A threat group impersonating the Electronic Frontier Foundation (EFF) is targeting Albion Online players through messages and decoy documents. The campaign uses malware such as stealer and to compromise player accounts. Analysis of an exposed directory revealed PowerShell scripts, PDFs, and malicious payloads. The infrastructure includes multiple servers sharing SSH keys. Code comments suggest developers. The attackers use EFF's reputation to lend credibility while executing malware in the background. The campaign exploits the game's player-driven economy, where in-game assets have real-world value. Mitigation strategies include cautious handling of unsolicited communications and verifying sources' authenticity.

External references